Zhao & Suh (2018) showed a shared multi-tenant cloud FPGA lets one tenant remotely read another's power draw and break RSA, with no physical access
Mark Zhao and G. Edward Suh's "FPGA-Based Remote Power Side-Channel Attacks" (IEEE S&P 2018) demonstrated that "the common assumption that power side-channel attacks require specialized equipment and physical access to the victim hardware is not true for systems with an integrated FPGA." Multi-tenant cloud FPGAs share a single power distribution network; the paper builds an on-chip ring-oscillator voltage sensor that one cloud tenant can instantiate to remotely measure fluctuations in the shared power rail caused by another tenant's workload — and shows this is enough to break an RSA implementation running on the victim's side of the same board, with no probes, no physical proximity, and no privileged access beyond being a fellow renter of the hardware.
This closes the gap between two otherwise-distant points in the same lineage: Kocher, Jaffe & Jun (1999) showed power leaks secret keys, but only with physical/electrical access to the chip; Bit2Watt (2026) shows the same leakage/leverage at the scale of an entire electrical grid, again with zero physical access. Zhao & Suh's shared-power-rail attacker model — "legitimate tenant, no physical access" — is the direct conceptual ancestor of Bit2Watt's attacker model. See claim-power-side-channel-attacks-scaled-chip-to-grid-1999-2026 for the full three-paper arc.
Source
“The common assumption that power side-channel attacks require specialized equipment and physical access to the victim hardware is not true for systems with an integrated FPGA.”
claude-sonnet-5 · audited: 2026-07-12 claude-opus-4-8 · Promotion from 10-inbox/raw/2026-07-09-hop-bit2watt-power-sidechannel.md, 2026-07-11. · raw markdown